Documentation
¶
Overview ¶
Package runtimeevidence is the fleet ingest use case for host runtime-reachability evidence (EPIC #1042 #1060/#1061). A host agent ships the shared libraries it observed loaded plus the OS packages that own them; this use case resolves the agent's canonical host asset and its hidden vulnerability engagement, then joins the evidence to that engagement's findings by PACKAGE OWNERSHIP, raising (never suppressing) the finding for a vulnerable library that actually loaded.
It holds no judgment-minting authority of its own: the join and the raise-only judgment come from the injected runtime attributor (internal/usecase/runtimereach), so this package stays a thin, tenant-bound ingest boundary. It is composition-root-only and must never be reached from the agent tool catalog.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Result ¶
type Result struct {
AssetID shared.ID
EngagementID shared.ID
Minted int
// Coverage echoes the host's declared runtime-evidence gaps (no eBPF privilege, an unreadable package
// database, an unsupported platform, a truncated sweep). It is carried back so the caller can record that
// this host reports partial or no runtime evidence. Coverage never suppresses a finding (runtime
// reachability is raise-only); it is observability, so the host's absence of evidence is honest, not silent.
Coverage []runtimereach.CoverageReason
// Pending is true when the host has no vulnerability engagement yet (its first SCA scan has not produced
// findings). The evidence is dropped for this sync; because attribution is idempotent and supersede-only,
// the agent's next report re-attributes against the populated findings. It is not an error.
Pending bool
}
Result reports what an ingest produced, for the agent-plane response and the audit trail.
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service ingests one agent's runtime-evidence report.
func NewService ¶
func NewService(resolver assetResolver, engagements engagementResolver, attributor runtimeAttributor) (*Service, error)
NewService validates its dependencies and returns the ingest service.
func (*Service) Ingest ¶
func (s *Service) Ingest(ctx context.Context, tenantID, agentID shared.ID, report runtimereach.Report) (Result, error)
Ingest resolves the agent's host asset and its hidden engagement, then attributes the runtime evidence to that engagement's findings. The tenant and agent identity come from the authenticated agent, never the body. A report with no evidence, or a host with no engagement yet, mints nothing and is not an error (runtime reachability is raise-only; its absence changes no verdict).